← All topics
CIPP — manage M365 tenants easily
approvedUsing CyberDrain CIPP to run multi-tenant Microsoft 365 operations: standards, GDAP, bulk actions, and consistent day-to-day administration.
Audiences: ae, tech · Tags: m365, multi-tenant, cipp, cyberdrain · Last verified: 2026-07-16
Teach module
# Teach — CIPP for multi-tenant M365 operations ## Core truths - CIPP (CyberDrain Improved Partner Portal) is an open-source, MSP-focused portal for administering many Microsoft 365 tenants from a single interface. - It uses GDAP (granular delegated admin privileges) relationships, aligning with Microsoft's model for least-privilege partner access. - Standards let you define desired tenant settings (for example, disabling shared mailbox sign-in, enabling unified audit log) and apply or enforce them across tenants. - Common day-to-day jobs — user offboarding, mailbox permissions, MFA state review, license reporting — can be done per tenant or in bulk without portal-hopping. - Because CIPP wraps Microsoft Graph, actions are consistent and scriptable rather than dependent on which admin portal a setting lives in this month. ## Common myths to correct - "Open source means unsupported" — CIPP has an active community, and a hosted/sponsored option exists for teams that do not want to self-host; either way, you own your operational process. - "It replaces our RMM/PSA" — CIPP is tenant administration, not device management or ticketing; it complements those tools. - "GDAP is just DAP with extra steps" — GDAP scopes roles per tenant and is what Microsoft requires; CIPP makes managing those relationships practical. ## Pitfalls - Deploying CIPP without agreeing internally which standards are enforced versus merely reported — silent enforcement surprises engineers. - Giving every technician full CIPP access instead of using role-based permissions within the tool. - Treating offboarding as done because the account is disabled: the full offboarding flow (sessions revoked, mailbox converted, licences reclaimed) is the value, use all of it. - Forgetting that standards run on a schedule: a manual portal change may be reverted by an enforced standard, which looks like a bug to the unaware.
Apply module
# Apply — discovery, objections, and talk tracks ## Discovery questions - How many different admin portals does a technician touch to fully offboard one user today? - How do you check MFA coverage across every tenant you manage — and how current is that answer? - When Microsoft changes a portal layout, how much time does your team lose relearning where settings live? - How do you evidence to a client that their tenant matches your security standard? - What is your current process for reclaiming unused licences across tenants? ## Objections and responses - "We manage fine in the portals." — Fine at what cost? Count minutes per task per tenant; multi-tenant portals turn a 20-minute job into a 2-minute one. - "Self-hosting is a burden." — The hosted option removes that; if self-hosting, the deployment is well documented and the operational win outweighs upkeep for most teams. - "Another tool for the team to learn." — CIPP consolidates several portals into one; the learning curve replaces portal-hopping rather than adding to it. ## Talk tracks - "One portal, every tenant, least-privilege by design" — leads with both efficiency and security posture. - Frame standards as the multi-tenant guarantee: what you promise every client is true, provably, all the time. - For AEs: the sale is the outcome (consistent, evidenced tenant management), not the tool name — CIPP is how delivery keeps that promise.
Convert module
# Convert — CTAs and next steps ## Approved CTAs - Internal enablement: each engineer completes one full user offboarding through CIPP this week and notes the time taken versus the portal method. - Offer clients a tenant health check: a standards report showing where their tenant deviates from our baseline. - Propose bringing unmanaged or ad-hoc tenants under managed standards as a defined onboarding package. ## Next-step framing - Tech sessions: next step is agreeing which standards are report-only versus enforced, then piloting on the MSP's own tenant. - AE sessions: next step is booking tenant health check conversations with the three clients most likely to fail an audit. - Never position CIPP output as a compliance certificate; it is evidence that supports compliance work.
Demo steps
# Demo — everyday multi-tenant jobs in CIPP 1. Show the tenant switcher and the all-tenants dashboard to establish the single-pane starting point. 2. Run a user offboarding on a test account: disable sign-in, revoke sessions, convert mailbox to shared, remove licences — one wizard, one screen. 3. Open the MFA report across all tenants and highlight how coverage gaps surface instantly. 4. Show standards: pick one standard (for example, enable unified audit log), show which tenants comply, and apply it to a pilot tenant. 5. Show the licence report across tenants and identify unassigned paid licences. 6. Open the GDAP relationship view to show scoped, per-tenant role assignments. ## Pre-demo checklist - Test user account created in the pilot tenant and safe to offboard. - Standards selected for the demo are report-only in advance, so nothing enforces mid-session. - Client-identifiable tenant names hidden for external audiences.
Claims policy
# Claims — CIPP ## Allowed claims - CIPP provides a single portal for administering multiple Microsoft 365 tenants. - CIPP uses GDAP relationships in line with Microsoft's partner access model. - Standards can report on or enforce defined tenant settings across tenants. - Common admin tasks (offboarding, MFA reporting, licence reporting, mailbox management) can be performed per tenant or in bulk. - CIPP is open source, with a hosted option available for teams that prefer not to self-host. ## Forbidden / needs-human-review claims - Specific sponsorship/hosting pricing — verify current figures before quoting. - Any guaranteed time savings percentage; use illustrative comparisons only. - Claims that a specific standard exists for a specific setting — verify against the current CIPP release before stating. - Claims about compliance certification outcomes. - Statements about CIPP's roadmap or unreleased features.